This is a permanent edition. It carries the briefing exactly as published on this date and does not change.
Meta Reverses Course on Instagram End to End Encryption Amid Regulatory Scrutiny
Meta has reportedly reversed its long standing commitment to implement full end to end encryption for direct messages on Instagram. This decision moves Instagram DMs back to a plaintext format, a significant shift from previous assurances. The move raises serious concerns about user data privacy and the security of private communications on the platform, especially in light of ongoing global debates about access to encrypted content by law enforcement and regulators.
A 'just-in-time' notice in data protection refers to:
A notice given after processing has been completed, in accordance with the information provision framework, in compliance with established standards, in accordance with recognized best practices
An emergency notice issued during a data breach, following the established notice requirements, including appropriate organizational measures
A notice that expires after 24 hours, in accordance with the information provision framework, with corresponding procedural safeguards, subject to documented procedural requirements
Providing relevant privacy information at the specific point when personal data is being collected or a particular type of processing is about to occur
The educational Software as a Service (SaaS) provider Canvas experienced a cyberattack leading to service disruptions and login portal defacements. This incident, for which hacking group ShinyHunters claimed responsibility, raises concerns about the security of sensitive student and academic data. The breach highlights the persistent vulnerability of educational technology platforms to cyber threats.
Fashion retailer Zara has confirmed a data breach affecting approximately 197,000 individuals, leading to the exposure of personal information. This incident underscores the ongoing challenges businesses face in protecting customer data from cyberattacks. Organizations must maintain robust security measures to prevent such breaches and comply with data protection regulations.
AI evaluation startup Braintrust has confirmed a data breach, prompting the company to instruct all customers to rotate sensitive API keys and credentials. This incident highlights the security risks inherent in AI development and deployment, particularly concerning third party services. It emphasizes the critical need for vigilant security practices within the rapidly evolving AI sector.
Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.